mirror of
https://github.com/larksuite/cli.git
synced 2026-07-03 14:02:43 +08:00
Introduce a typed error contract framework for lark-cli so in-process
Go callers can branch via errors.As(&errs.XxxError{}) and shell scripts,
AI agents, and protocol adapters can branch on stable JSON type/subtype
fields instead of regex-parsing free-form messages.
Adds:
- Canonical taxonomy under errs/ (9 categories + typed Error structs
embedding a shared Problem, RFC 7807-aligned)
- Centralized Lark code metadata + identity-aware BuildAPIError dispatch
- Typed JSON envelope writer alongside the legacy envelope writer
- MCP / OAuth (RFC 6750 Bearer) projection adapters
- Five CI lint guards preventing ad-hoc taxonomy drift
Backward compatibility: legacy *output.ExitError producers (ErrAPI,
ErrWithHint, Errorf, ErrBare) and business shortcuts that use them
continue to render the legacy envelope unchanged. SecurityPolicyError
wire format and exit code are preserved via a carve-out; taxonomy
migration is deferred to PR 2. Domain-specific business migration is
staged across PR 3+.
Framework-direct paths now return typed *errs.*Error: ErrAuth /
ErrValidation / ErrNetwork emit category literals on the wire
(authentication / validation / network), *core.ConfigError is promoted
at the cmd/root boundary with exit code aligned from 2 to 3, and Lark
API permission denials classified by BuildAPIError exit 3.
At the SDK boundary, WrapDoAPIError preserves any already-classified
error (legacy *output.ExitError or typed *errs.*) so output.ErrAuth
from missing credentials surfaces with the auth category and exit 3
intact instead of being downgraded to a network error. Policy responses
classified by BuildAPIError (codes 21000 / 21001) extract challenge_url
and the canonical hint from the response body, matching what the
auth transport already surfaces at the HTTP layer; non-https
challenge URLs are dropped.
First PR in the feat/error-contract-* series.
34 lines
1.1 KiB
Go
34 lines
1.1 KiB
Go
// Copyright (c) 2026 Lark Technologies Pte. Ltd.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
// Package lintapi defines the shared types every lint domain returns from
|
|
// its scan entry point. New lint domains (sibling packages under lint/)
|
|
// MUST return []lintapi.Violation so cmd/main can aggregate and report
|
|
// uniformly. The domain may add its own private types for internal use.
|
|
package lintapi
|
|
|
|
// Action enumerates the response modes for a violation.
|
|
type Action string
|
|
|
|
const (
|
|
// ActionReject hard-fails CI. Only REJECT contributes to a nonzero
|
|
// lintcheck exit code.
|
|
ActionReject Action = "REJECT"
|
|
// ActionLabel emits a diagnostic so CI can label the PR but does not fail.
|
|
ActionLabel Action = "LABEL"
|
|
// ActionWarning surfaces a reviewer-attention note without failing CI.
|
|
// CI does NOT exit nonzero on warnings; they are reviewer signal only.
|
|
ActionWarning Action = "WARNING"
|
|
)
|
|
|
|
// Violation describes a single lint hit. Rule identifies which check
|
|
// produced it; the domain package owns the rule namespace.
|
|
type Violation struct {
|
|
Rule string
|
|
Action Action
|
|
File string
|
|
Line int
|
|
Message string
|
|
Suggestion string
|
|
}
|